Soru

Zorluk: OrtaInfrastructure Migration with AWS Application Migration Service (MGN)

A gaming publisher is migrating its legacy multiplayer matchmaking and lobby servers from an on-premises data center to AWS using AWS Application Migration Service (MGN). The hybrid network architecture consists of an AWS Site-to-Site VPN terminating on an AWS Transit Gateway that is attached to a staging VPC. The source servers are in a highly secure zone with no direct route to the public internet and must perform data replication strictly over the private VPN connection.

After installing the AWS replication agent on the source servers, the replication status shows as stalled, and the agent logs indicate a connection timeout when attempting to reach the replication servers in the staging VPC.

Which two configuration steps must the Solutions Architect perform to resolve this connectivity issue? (Select TWO.)

  1. Modify the AWS Application Migration Service staging area settings to use a private IP address for data routing, and configure the replication security group in the staging VPC to allow inbound traffic on TCP port 1500 from the on-premises subnet range.Cevap
  2. Configure the on-premises firewall to allow outbound traffic on TCP port 1500 to the staging VPC CIDR block, and verify that the Transit Gateway route tables have propagation or static routes configured for both the on-premises and staging VPC attachments.Cevap
  3. C
    Deploy a NAT Gateway in the staging VPC public subnet, update the staging subnet route tables to direct all 0.0.0.0/0 traffic to the NAT Gateway, and configure the on-premises firewall to accept incoming connections over TCP port 443.
  4. D
    Create an Amazon Route 53 Private Hosted Zone for the Application Migration Service control plane interface VPC endpoint in the staging VPC, and associate the hosted zone with the on-premises DNS server to resolve replication target hostnames.
  5. E
    Configure a Direct Connect Gateway directly attached to the staging VPC to handle transitive VPC-to-VPC traffic, and configure the source servers to route replication traffic over TCP port 8080.

Cevap

Modify the AWS Application Migration Service staging area settings to use a private IP address for data routing, allow inbound traffic on TCP port 1500 in the replication security group, permit outbound traffic on TCP port 1500 on the on-premises firewall, and configure Transit Gateway route tables to allow private routing between the attachments.
To achieve private replication over the VPN connection, the AWS Application Migration Service must be configured to route data over private IP addresses. Because data replication occurs strictly over TCP port 1500, the replication security group in the staging VPC must permit inbound port 1500 traffic from the on-premises subnets, the on-premises firewall must permit outbound port 1500 traffic to the staging VPC CIDR, and the Transit Gateway route tables must have valid routing configurations for both attachments.

Adım Adım Çözüm

1
Configure private IP address usage for replication traffic in the AWS Application Migration Service (MGN) staging area settings.
Ensures that replication servers are assigned and use private IP addresses for data replication instead of public IP addresses.
This complies with the security requirement to restrict replication data traffic to the private VPN connection.
2
Ensure firewall rules and security groups permit TCP port 1500 traffic.
Allows replication agents to establish the data channel to the replication servers.
AWS MGN performs data replication strictly over TCP port 1500, which must be open bidirectionally between source and replication subnets.
3
Verify Transit Gateway routing between the on-premises network and the staging VPC.
Enables transitive routing of packets across the private Site-to-Site VPN to the staging subnets.
Without proper route propagation or static routes in the Transit Gateway route table, packets cannot reach their destination across the attachments.

Anahtar Kavram

Configuring secure private network data replication for AWS Application Migration Service (MGN) over VPN and Transit Gateway using private IP routing and TCP port 1500.
Tahmini Süre:2m 0s
Bu soruyu puanla